Approved For@Iease Soulirds) eM Rb Adeao1 ae 1-9 


MEMORANDUM FOR: Chief, Physical Security Division, 


FROM: aes 
Chief, Industrial Security Branch, 


Office of Security 


SUBJECT: ISB Universe 


Sir Donal: 
Recalleth your 2 November 1979 charge to: 
a. Define our universe 
Ds Describe our target 
om Accent reaudits 


Complieth we with a and b 

but nothing was done about category c; 

for research has shown 

that items unknown 

surfaced reasons for defying thee. 25X1A 


Our universe was defined for us in February 1978 by the 
D/OS paper setting forth the Branch's mission. The primary 
mission then, as now, is to conduct periodic, unannounced conm- 
prehensive security audits of Agency contractor facilities. 
To implement these audits, we obtained from OD&E and OL a com- 
posite list of JFontractors involved with classified Agency 
contracts. These represent all of_our_audit possibilities but 
hardly our probabilities, as about of the contractors on Pet | 
the list are very small and have classified contracts only be- 
cause Agency interest must be hidden. As the information is 
usually one or two sterilized contracts, for some reason classi- 
fied CONFIDENTIAL, it would be folly to attempt to audit all. 25X1A 


25X 
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25X1A 


Thus, our real world becomes more like contractors who have 
significant amounts of Agency informat hat requires pro- 
tection. This figure has been determined through the following 


research. 25X1A 
As you may recalleth, OL submitted a list of Mcontractors 
to be audited and prioritized them ''A' and '"B.'' They used as the 
basis for their "A" prioritization 
a. Did the company have SI/TK as part of the contract 
be Did they have a TS contract 


Cc. Did they have a long time relationship with the Agency 


- j f the above, they were rated 
Aare were placed in this category. 
25X1A 


OD&E supplied a list of contractors and prioritized them 
one, two, and three. They used as the basis for their prioriti- 
zation, SCI contracts at a company and the dollar 


value. contractors were neofBpe co heal Ler 25X1A 


category , aly category "3."" Since D&E contra lso 
have contracts wl L, we were provided a total of epa- 
rate contractors to audit. 25X1A 


After ISB had conducted about 85 audits, it became apparent25X1A 
that most of the major companies had been audited. So in Aug 
1979, we asked OL and OD&E to supply an up-to-date listing oi 
contractors they would like to see audited during th t fi 
year. OL responded wich ill OD&E only furnished ames eXx- 
plaining that these repr ed their remaining companies that 25X1A 
had not been audited. 


Recently ISB conducted audits at four priority "A" companies 
and found no active contracts. One of these companies was se- 
lected from the OD&E list while the other three were from the OL 
list. Prior to the audits, ISB personnel conducted thorough re- 
search which included interviews with cognizant Industrial Secu- 
rity Officers. The auditors left for the audits with the belief 
that there was at least one active contract at these firms. AI1l 
they found were residuals. 

Corctiac (3. 


— 
Completely hs a Mee Acemraih fern 
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25X1A 


These experiences cast doubts on the validity of the Webal 
lists, and we had already audited all of those (except coxa 
prioritized category "A" because of SI/TK or TS; the third cri- 
teria of OL, longevity, seemed to be the culprit. Before making 
any. conclusions, however, an effort was made to ascertain if OL 
and OD§E had supplied us with a complete listing of companies 
that should be rated "A" by their own criteria. 

25X1A 


OL was asked to supply a list o contractors who had 
SI/TK. They responded with a list spe they advised was 
incomplete. Nevertheless there were e1g on the list that had 
not been previously furnished. The Special Security Center also 
attempted to furnish a list of SI/TK. facilities by tasking their 
computers to come up with a listing of all Agency-sponsored SI/TK 
accesses jp industry. From this list we were able to develop the 
names of companies that had SI/TK facilities. These companies, 
however, either been audited by us in the past or appeared on 
other lists. Therefore, they were unable to furnish any addi- 
tional names. 


The latest CO computer printout was reviewed page by page. 
The printout lists ontractors with TS contracts that were not 


listed on the prio lists previously furnished. It should be 
noted, however, that most are recent additions, and some have 
very small contracts. Mest OF THRE DE Wekk Ar HO~ MO CLéSSHED 
WERK OR SPRAGE AP THE Fcners. 
Thus we have an addition of 38 companies that we can add to 
our priority listing from OL. 
25X1A 


Contact was also made vith who assists in 
the preparation of the OD&E STE computer printout. He advised 
that he would be able to furnish a special printout that would 

rovide a total alphabetical listing of all contractors in the 
Mor that were Agency connected, along with the status of 
e contract, the dollar value, and the scheduled date of com- 
pletion. In the future, he will furnish this run on a quarterly 
basis. The initial run listed eight contractors not previously 


This research then has developed the names of ontractors 

who can be considered priority "A" without resorting to use of 
the "longevity" criteria. It seems tomxe that a far better cri- 
teria than longevity would be a criteria based on number of 
classified contracts and dollar value. The CONIF run was reviewed 
page by page, and 15 new audit possibilities were discovered 
using this criteria. 

De arseiojpy oF Werk 13 SerTER S94 ZI 
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25X1A 


In view of the ab hat our auditable 
universe becomes about hat we have already 
done plus approximatel ewly di companies), At- 25X1A 
tached are 5 lists doc ing research done to develop the Pi 


companies. 25X1A 


Describe the Target: I believe our et is time limited. 
Now that we have developed a resdvoir of ew companies to 
audit, this should be sufficient to carry us to the next fiscal 
year, especially if, as planned, some reaudits will be injected. 
However, after that, most of the “significant Priority A" con- 
tractors will have been audited feel strongly that we should 
not attempt to audit all of che I= the small companies can VY 
be very adequately checked thro spections by ISO's. There25X1A 
fore, it appears that during the next 9 months our targets will 
be contractors on our new priority lists plus periodic reaudits. 
After that our targets should be reaudits plus any new contrac- 
tors in the priority "A" category that may enter the scene. 
This should then put the reaudits on a 2-year-plus cycle. I 
feel this is acceptable, for to reaudit in less then 2 years 
would constitute harrassment. 


In the future, ISB will prepare all lists of contractors to 
be audited from our own research and will only rely on OL and 
OD&E to furnish us with companies they want audited for special 
reasons. Additionally, a general audit list will be prepared 
before each quarter and coordinated with OL and OD§&E. 


This coordination is essential to preclude going to com- 
panies just inspected by ISO's, going to companies where con- 
tracts have been recently cancelled, and to allow them to voice 
any operational objections they may have prior to the audit 
being set up for a specific audit date. 


I hopeth this prose has élightened thee 
regarding the future course of ISB, 

but if this falls short 

of an adequate report 

someone else will revise it, not me! 
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